CVE-2026-45125: Php Mail Header Crlf Injectioncve-2026-45125-php-mail-header-crlf-injection
Unsanitized user input reaches email headers in build_message() without CRLF cleanup, which can allow CRLF injection to inject arbitrary email headers or alter message structure.